Every CVE whose affected-product data names Johnsoncontrols Xaap, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-34490 — CVSS 5.5 (medium): Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken…